CVE-2025-37101

Published Jun 26, 2025

Last updated 22 days ago

Overview

Description
A potential security vulnerability has been identified in HPE OneView for VMware vCenter (OV4VC). This vulnerability could be exploited allowing an attacker with read only privilege to cause Vertical Privilege Escalation (operator can perform admin actions).
Source
security-alert@hpe.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.7
Impact score
5.8
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Severity
HIGH

Weaknesses

security-alert@hpe.com
CWE-269

Social media

Hype score
Not currently trending